SECURITY FINDING

Malware hidden in WordPress database settings

What it is

A suspicious value was found in WordPress's internal settings (the "options" table, loaded on every single page view) — a favorite hiding spot for malware because it keeps running without needing its own file.

How to fix it

If you're comfortable with databases, review that specific setting yourself; otherwise a WordPress Plugin AI Repair backs up first and can clean it safely. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.

In depth

Our security scan found malicious code injected into your WordPress database options, which are core settings your site loads on every page view. Because this code runs automatically whenever someone visits your site, attackers use it to inject spam links, redirect visitors to malicious sites, steal data, or serve unwanted ads. This type of infection can damage your site's search rankings and visitor trust. To fix this, use a WordPress security plugin like Wordfence or Sucuri to scan for and remove the malicious code automatically. If you prefer a manual approach, contact your hosting provider's support team to restore your site from a clean backup from before the infection occurred.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.